CVE-2022-27404 is a critical heap buffer overflow vulnerability affecting FreeType, specifically within the sfnt_init_face function, and impacts various Fedora Project distributions of FreeType. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.0CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-27404
May 9, 2023FreeType: Buffer overflow in sfnt_init_face
Apr 22, 2022FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Apr 12, 2022